漏洞描述
FRP default login credentials were discovered.
id: frp-default-login
info:
name: FRP Default Login
author: pikpikcu
severity: high
verified: false
description: FRP default login credentials were discovered.
reference:
- https://github.com/fatedier/frp/issues/1840
tags: frp,default-login
created: 2023/06/24
rules:
r0:
request:
method: GET
path: /api/proxy/tcp
headers:
Authorization: "Basic YWRtaW46YWRtaW4="
expression: response.status == 200 && response.body.bcontains(b'proxies')
expression: r0()